Previous Topic: Affiliations for Single Sign-On

Next Topic: Configure Affiliations

Affiliations for Single Logout

When a Service Provider generates a logout request, it checks if the Identity Provider belongs to an affiliation and sets an attribute in the request to the affiliation's ID. The Identity Provider receives the request and checks that the Service Provider belongs to the affiliation identified in the attribute.

The Identity Provider obtains the affiliation Name ID from the Session Server's session store. When the Identity Provider issues logout request messages to all session participants, it includes the affiliation Name ID for the members of the affiliation.


Copyright © 2010 CA. All rights reserved. Email CA about this topic